Privacy Policy

1. Data controller

Owner: company in the process of incorporation. The full legal identification (company name, tax ID, registered address and travel agency registration) will be published here before commercial launch.

2. Data we process

  • Booking data: first name, last name and email of the booking holder (phone optional), dates, hotel and occupancy of the stay.
  • Account data: email verified via magic link.
  • Payment data:transaction references and status. Payment is processed by the payment provider (Stripe, or our wholesale provider's payment processor depending on the mode): we never store card numbers.
  • Technical records: IP address and application activity logs (security, rate limiting and diagnostics).

3. Purposes and legal bases

  • Performance of the contract (art. 6.1.b GDPR): managing the booking with the hotel through our wholesale provider, issuing the voucher, handling changes, cancellations and refunds.
  • Legal obligation (art. 6.1.c): invoicing, accounting and tax obligations.
  • Legitimate interest (art. 6.1.f): fraud prevention, service security (rate limiting, logs) and defence against claims.

We make no automated decisions with legal effects and do no commercial profiling.

4. Recipients

  • Our wholesale booking provider: receives the booking holder data required to confirm the booking with the hotel, and processes the payment when the provider-charged mode is in force.
  • The hotel you book: holder/guest details for check-in.
  • Stripe (payments, when 0xTravel charges you).
  • Resend (transactional email: sign-in links, vouchers, cancellations).
  • OpenStreetMap: the map embedded on each hotel page is served from openstreetmap.org, which receives your IP address when it loads.

Some of these providers are outside the EEA (e.g. the US). Transfers rely on adequate safeguards: adequacy decisions (such as the EU-U.S. Data Privacy Framework) or the European Commission's standard contractual clauses.

5. Retention periods

  • Bookings, payments and invoicing: 6 years from the transaction (art. 30 of the Spanish Commercial Code and tax regulations).
  • Account: while you keep it active; deleted upon your request.
  • Technical logs: purged periodically (by default, after 30 days).

6. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to contact@0xtravel.xyz. You can also lodge a complaint with the Spanish Data Protection Agency (aepd.es).

7. Security

All traffic is encrypted (TLS), sessions use signed httpOnly cookies, secrets are handled server-side only and administrative access is restricted. We store no payment credentials.